Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

22 / 52 results
Active filter:tag: #supply-chain✕ clear
Miasma credential-stealing framework source code leaked on GitHubhighbug_reportVulnerability
bug_reportVulnerability

Miasma credential-stealing framework source code leaked on GitHub

Open-source software ecosystems and their supply chains. Organizations consuming packages from public repositories (npm, PyPI, RubyGems, etc.) are at increased risk. No specific vendor or product version affected; threat is ecosystem-wide.

BleepingComputer18:27 UTC
Microsoft GitHub repos compromised, 73 disabled for distributing malwarehighbug_reportVulnerability
bug_reportVulnerability

Microsoft GitHub repos compromised, 73 disabled for distributing malware

73 repositories across Microsoft's official GitHub organizations (Azure, microsoft, Azure-Samples, MicrosoftDocs). Organizations using Microsoft sample code, Azure templates, or CI/CD pipelines referencing these repositories are potentially affected.

Microsoft13:42 UTC
PyPI supply chain attack: 19 packages with auto-executing credential stealerhighbug_reportVulnerability
bug_reportVulnerability

PyPI supply chain attack: 19 packages with auto-executing credential stealer

PyPI repository: 19 compromised packages containing 37 malicious wheel artifacts. Affects Python developers who installed these packages. Attack uses .pth files for automatic execution during pip install, targeting credential theft via Bun-based stea…

PyPI07:13 UTC
PyPI supply-chain attack: 19 science packages compromised with malwarehighbug_reportVulnerability
bug_reportVulnerability

PyPI supply-chain attack: 19 science packages compromised with malware

19 science-focused Python packages on PyPI, collectively downloaded hundreds of thousands of times. Specific package names and versions not disclosed in summary. Affects Python developers using PyPI packages in scientific/research workflows.

BleepingComputer18:41 UTC
Miasma worm compromises 73 Microsoft GitHub repos in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

Miasma worm compromises 73 Microsoft GitHub repos in supply chain attack

73 Microsoft GitHub repositories across four organizations: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. GitHub has disabled access to affected repositories.

Microsoft04:58 UTC
Toshiba, Muji sites show credential-stealing prompts via polyfill supply chainhighbug_reportVulnerability
bug_reportVulnerability

Toshiba, Muji sites show credential-stealing prompts via polyfill supply chain

Toshiba and Muji public websites, potentially other sites using the compromised third-party polyfill library. Scope of affected sites and specific polyfill service not yet confirmed.

Toshiba19:54 UTC
npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkitcriticalbug_reportVulnerability
bug_reportVulnerability

npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkit

npm ecosystem: over 50 compromised legitimate packages. Affects developers using npm for JavaScript/Node.js projects. IronWorm targets developer credentials and source code with eBPF kernel-level persistence.

npm16:05 UTC
Red Hat npm packages compromised with Miasma credential stealerhighbug_reportVulnerability
bug_reportVulnerability

Red Hat npm packages compromised with Miasma credential stealer

Over 30 npm packages in the '@redhat-cloud-services' namespace on npm registry. Affects developers and CI/CD pipelines consuming these packages. Specific package names and versions not yet disclosed.

Red Hat19:38 UTC
Miasma supply chain attack compromises Red Hat npm packagescriticalbug_reportVulnerability
bug_reportVulnerability

Miasma supply chain attack compromises Red Hat npm packages

Red Hat Cloud Services npm packages (@redhat-cloud-services scope). Affects developers and CI/CD pipelines using these packages. Scope includes any environment where compromised packages were installed.

Red Hat15:40 UTC
Malicious npm package codexui-android steals OpenAI tokens, 29K downloadshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm package codexui-android steals OpenAI tokens, 29K downloads

npm package codexui-android (all versions). Targets developers using OpenAI Codex APIs. Affects organizations with Node.js/npm development environments where this package was installed.

OpenAI07:31 UTC
33 malicious npm packages deployed in dependency confusion recon campaignhighbug_reportVulnerability
bug_reportVulnerability

33 malicious npm packages deployed in dependency confusion recon campaign

npm ecosystem; organizations using private npm packages with names vulnerable to dependency confusion attacks. Affects developer workstations, CI/CD pipelines, and build environments that may inadvertently install public packages instead of intended…

npm22:06 UTC
Malicious NuGet package "Sicoob.Sdk" steals banking credentialshighbug_reportVulnerability
bug_reportVulnerability

Malicious NuGet package "Sicoob.Sdk" steals banking credentials

NuGet package "Sicoob.Sdk" versions 2.0.0 through 2.0.4. Targets developers integrating with Sicoob (Brazilian cooperative banking system). Affects .NET development environments where the malicious package was installed.

Sicoob07:11 UTC
Malicious npm package targets Claude AI user data directoryhighbug_reportVulnerability
bug_reportVulnerability

Malicious npm package targets Claude AI user data directory

npm package "mouse5212-super-formatter" (all versions). Targets developers using Anthropic Claude AI tools with access to /mnt/user-data directory. Affects Node.js development environments where the malicious package was installed.

npm13:44 UTC
Glassworm botnet targeting developers disrupted via C2 takedownhighbug_reportVulnerability
bug_reportVulnerability

Glassworm botnet targeting developers disrupted via C2 takedown

Software developers and development environments targeted by Glassworm botnet. The botnet leveraged Solana blockchain and BitTorrent DHT for command-and-control infrastructure, indicating attacks against software supply chains.

BleepingComputer11:28 UTC
CrowdStrike, Google disrupt GlassWorm C2 targeting software developershighbug_reportVulnerability
bug_reportVulnerability

CrowdStrike, Google disrupt GlassWorm C2 targeting software developers

Software developers using third-party packages and browser extensions. GlassWorm campaign active since early 2025, distributing malware through supply chain vectors including malicious packages and extensions.

CrowdStrike09:48 UTC
TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.iocriticalbug_reportVulnerability
bug_reportVulnerability

TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.io

34+ malicious packages (384+ versions) distributed across npm (Node.js), PyPI (Python), and Crates.io (Rust) repositories. Campaign active since May 2026. Affects developers and CI/CD pipelines consuming packages from these ecosystems.

npm03:59 UTC
Laravel Lang packages compromised to deliver credential-stealing malwarehighbug_reportVulnerability
bug_reportVulnerability

Laravel Lang packages compromised to deliver credential-stealing malware

Laravel Lang localization packages distributed via Composer. Affects developers who installed or updated compromised packages during the attack window. Specific package names and versions not yet publicly disclosed.

Laravel18:48 UTC
Supply chain attack compromises 8 Packagist packages with malicious binaryhighbug_reportVulnerability
bug_reportVulnerability

Supply chain attack compromises 8 Packagist packages with malicious binary

Eight Composer packages on Packagist containing JavaScript components. Malicious code injected into package.json files executes a Linux binary from GitHub Releases. Downstream projects using these packages are affected.

Packagist14:07 UTC
Laravel-Lang packages compromised to deliver credential-stealing malwarehighbug_reportVulnerability
bug_reportVulnerability

Laravel-Lang packages compromised to deliver credential-stealing malware

Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages.

Laravel-Lang07:51 UTC
Compromised @antv npm packages deploy credential-stealing malwarecriticalbug_reportVulnerability
bug_reportVulnerability

Compromised @antv npm packages deploy credential-stealing malware

Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.

npm15:48 UTC
Grafana breach via unrotated GitHub token after TanStack npm compromisehighbug_reportVulnerability
bug_reportVulnerability

Grafana breach via unrotated GitHub token after TanStack npm compromise

Grafana Labs infrastructure. Organizations using Grafana products are not directly affected by the breach itself, but should monitor for potential secondary impacts.

Grafana13:46 UTC
Over 600 malicious npm packages published in Shai-Hulud campaignhighbug_reportVulnerability
bug_reportVulnerability

Over 600 malicious npm packages published in Shai-Hulud campaign

npm ecosystem: 600+ malicious packages published by threat actors. Affects organizations using npm for JavaScript/Node.js dependency management. Specific package names not provided in summary.

npm12:30 UTC